Cybersecurity Compliance
RBI Cyber Security Framework: A Complete 2026 Compliance Guide
The Reserve Bank of India (RBI) has, since its 2016 circular, steadily expanded cyber-security expectations for banks, NBFCs, payment aggregators and payment gateways. If your organization is RBI-regulated, cyber security is no longer optional hygiene - it is a supervised, auditable obligation with real penalties for gaps. This guide breaks down what the RBI Cyber Security Framework actually requires and how to become and stay compliant.
Who the RBI Cyber Security Framework applies to
The framework's expectations reach across the RBI-regulated ecosystem: scheduled commercial banks, cooperative banks, NBFCs (with tiered obligations by size), and - through separate but related Master Directions - payment aggregators (PA) and payment gateways (PG).
Crucially, the depth of controls scales with your risk and size. A large private bank faces a far more prescriptive baseline than a base-layer NBFC, but every regulated entity must demonstrate governance, monitoring, and incident response.
Core controls the framework expects
- A board-approved cyber-security policy, distinct from the broader IT policy
- A named Chief Information Security Officer (CISO) with a direct reporting line
- Baseline security controls: network segmentation, secure configuration, patch and vulnerability management
- Continuous surveillance - a SOC or managed detection capability with defined escalation
- Vulnerability Assessment and Penetration Testing (VAPT) of critical and internet-facing systems
- Application security testing across net-banking, mobile banking and APIs
- Vendor / third-party risk management and outsourcing controls
- Incident response, business continuity (BCP) and disaster recovery (DR) that is tested, not just documented
VAPT and application security under RBI
RBI expects regular, credible VAPT - not a once-a-year checkbox scan. Testing should cover the OWASP Top 10 and business-logic flaws, be performed by competent testers, and produce risk-rated findings with proof-of-concept and clear remediation.
For customer-facing channels (net-banking, UPI apps, mobile banking), application security testing to a recognized standard (OWASP WSTG / MASVS) is expected, and findings must be tracked to closure with re-testing.
Incident reporting and data localization
RBI-regulated entities must report material cyber incidents promptly. This dovetails with CERT-In's directions requiring reporting of listed incidents within six hours of detection - so your incident-response runbook must be built for that timeline.
RBI also enforces payment-data localization: data relating to payment systems must be stored within India. Architecture and vendor choices need to reflect this from the design stage, not as an afterthought.
How to become and stay RBI-compliant
- Run a gap analysis of your current controls against the framework and applicable Master Directions
- Close technical gaps: segmentation, hardening, logging, MFA, and a real monitoring capability
- Establish governance: board-approved policy, CISO, and a reporting cadence
- Schedule recurring VAPT and application security testing with tracked remediation
- Build and rehearse an incident-response plan aligned to the 6-hour CERT-In timeline
- Maintain a defensible evidence pack for supervisory review
Need help with this in practice?
A5 Cyber Nexus audits, remediates and certifies against these frameworks.
Frequently asked questions
How often is VAPT required under RBI guidelines?
RBI expects regular VAPT of critical and internet-facing systems - at minimum annually, and after any significant change. High-risk, customer-facing systems are often tested more frequently. Findings must be remediated and re-tested.
Does the RBI framework require a CISO?
Yes. RBI expects a named CISO with an independent reporting line to senior management/the board, responsible for the cyber-security program and incident governance.
Is data localization mandatory under RBI?
For payment-system data, yes - RBI requires it to be stored within India. Your architecture, cloud region choices and vendor contracts must reflect this.
Make it accessible.
Make it attack-ready.
Prove both before launch.
Bring us your app, audit deadline, or security concern. We'll map the fastest path to WCAG conformance, VAPT coverage, and regulator-ready evidence.
